Legal

Privacy Policy

What we do with personal data, why, and what you can do about it. Written to be read rather than to be survived, and covering both India's DPDP Act and the UK and EU GDPR.

Last updated 12 September 2026

01Who we are

Brillaince is a brand and reputation intelligence platform operated by DAV Media. This policy explains what personal data we handle, why, on what legal basis, and what you can do about it.

We act in two distinct roles, and the difference decides which rights apply and who you should approach first.

As controller, or Data Fiduciary
For our own website visitors, enquiries, marketing contacts and the administration of client accounts. We decide why and how that data is processed, so requests about it come to us directly.
As processor, or Data Processor
For the workspaces we run on behalf of a client brand or agency. There, the client decides what is monitored and we act on their documented instructions. If your data appears inside a client's workspace, that client is the controller and we will route your request to them.

02What we collect

Enquiries
Name, work email, company, role and whatever you write in the message when you use the contact form or email us.
Account data
Name, work email, organisation, role and authentication records for people who use the platform.
Usage data
Pages viewed, features used, approximate location derived from IP, browser and device type. Used to keep the service working and to understand which parts of it earn their place.
Billing data
Company details and invoicing records. Card details are handled by our payment provider and never reach our systems.
Monitored content
Publicly available news articles, social posts, videos and AI-generated answers that mention a brand our client tracks. This can include personal data such as an author's name, handle, public profile and the content they published.
Support correspondence
Messages you send us and our replies, kept so we can pick up a thread where it left off.

We do not collect special category or sensitive personal data on purpose. Where it appears incidentally inside published content, we process it only as part of that content and never build profiles on individuals as individuals.

03Personal data we did not collect from you

This section applies if you are a journalist, creator, commentator or member of the public whose published content has been picked up by the platform, rather than a client or a website visitor.

The service reads content that is already public: news coverage, public social posts, public video, and answers produced by AI assistants. We did not obtain that content from you, so under Article 14 of the GDPR you are entitled to know where it came from and what happens to it.

Source categories
Licensed press and news feeds, licensed social listening providers, public web and video sources, and public AI assistant outputs. We do not scrape private or access-restricted platform data.
What we do with it
It is deduplicated, classified by topic, scored for sentiment and relevance, and shown inside the workspace of the brand it mentions. We do not sell it, use it for advertising, or enrich it with data from other sources about you.
Legal basis
Legitimate interests: the interest of a brand in understanding what is published about it, balanced against your rights. We restrict processing to content you published publicly and to the purpose of brand reputation analysis. In India, this is processing of publicly available personal data you have made public.
Your options
You can object to processing, ask for a correction, or ask us to suppress a specific author or source from the analysis. Where we act as processor for a client we will pass the request to them and support them in answering it.

To exercise any of this, write to privacy@brillaince.com with the URL or post in question. You do not need an account, and we will not ask you to create one.

04Why we process it, and on what basis

To answer an enquiry
Legal basis: steps taken at your request before entering a contract, and our legitimate interest in replying to people who contact us.
To provide the platform
Legal basis: performance of the contract with the client organisation.
To keep the service secure and working
Legal basis: legitimate interests in the integrity, security and reliability of the service.
To bill and keep records
Legal basis: legal obligation, and performance of contract.
To send occasional product or industry email
Legal basis: consent where required, or legitimate interests for existing business contacts. Every message carries an unsubscribe link that works.
To analyse brand coverage on a client's behalf
Legal basis: legitimate interests of the client brand, with us acting as processor under a data processing agreement.

Under the DPDP Act, where consent is the basis, you may withdraw it at any time and with the same ease as it was given. Withdrawal does not undo processing that already took place lawfully.

05Automated processing and AI

The platform scores sentiment, classifies topics and ranks signals automatically, and it drafts suggested responses. Two things follow from that, and we would rather state both than be asked.

  • No automated decision with a legal or similarly significant effect is made about any individual. Scoring applies to content and to brands, not to people as subjects of a decision.
  • Nothing is published, sent or posted by the platform. Drafts are drafts. A person at the client organisation reviews and decides.

Where content is processed by a third-party model to produce an analysis or a draft, it is sent under agreements that prohibit using that content to train the provider's models.

06Who we share it with

We do not sell personal data. We share it only with the following categories of recipient, each under contract.

Infrastructure and hosting providers
To run and store the service.
Data and licensing providers
Press, social and video sources we license content from.
AI model providers
For analysis and drafting, under no-training terms.
Email, support and analytics tools
To reach you and to keep the service working.
Payment providers
To take payment. They handle card data; we do not.
Professional advisers and authorities
Where we are legally required, or to establish or defend a legal claim.

A current list of sub-processors is available to clients on request, and we give notice before adding a new one that processes client data.

07International transfers

DAV Media operates from India and the United States, and some of our providers operate elsewhere. That means personal data may be transferred across borders.

  • For transfers out of the UK or EEA we rely on adequacy decisions where they exist, and otherwise on Standard Contractual Clauses together with a transfer risk assessment.
  • For transfers out of India we comply with the DPDP Act and any restrictions notified by the Central Government.
  • Clients with data residency requirements should raise them before onboarding, so we can confirm what we can and cannot commit to rather than discovering it later.

08How long we keep it

Enquiries
Up to 24 months from the last contact, unless you ask us to delete them sooner.
Account data
For the life of the account, then up to 12 months after closure.
Monitored content in a workspace
For the retention period agreed with the client, and deleted or returned on termination in line with the data processing agreement.
Billing records
As long as tax and company law requires, typically eight years in India.
Security and access logs
Up to 12 months.

When a retention period ends, data is deleted or irreversibly anonymised. Where deletion from backups is not immediately possible, it is isolated from active use until the backup cycle expires.

09Your rights

Depending on where you are, you have some or all of the following. We do not charge for exercising them and we do not require an account.

  • Access: a copy of the personal data we hold about you, and a summary of how it is processed.
  • Correction: have inaccurate or incomplete data corrected or completed.
  • Erasure: have data deleted where we no longer have a lawful reason to keep it.
  • Restriction: have processing paused while a dispute about accuracy or basis is resolved.
  • Objection: object to processing based on legitimate interests, including the monitoring described above.
  • Portability: receive data you gave us in a structured, machine-readable format.
  • Withdraw consent: where processing relies on consent, withdraw it at any time.
  • Nomination, under the DPDP Act: nominate another person to exercise your rights in the event of death or incapacity.
  • Complain: to us first, and then to a supervisory authority. In India, the Data Protection Board. In the EU or UK, your local supervisory authority.

Write to privacy@brillaince.com. We respond within 30 days, and tell you before that if a request will take longer and why.

10Grievance redressal

The DPDP Act requires a named route for grievances. Ours is grievance@brillaince.com, which reaches the Grievance Officer for Brillaince.

Raise anything here that a normal support conversation has not resolved: a request we declined, a delay, or a concern about how data is being handled. We acknowledge within 72 hours and resolve within 30 days.

11Cookies

This website uses the smallest set of cookies it can. We do not run advertising cookies and we do not sell behavioural data.

Strictly necessary
Security, load balancing and remembering your cookie choice. These cannot be switched off and do not require consent.
Analytics
Aggregate page and feature usage, so we can tell which parts of the site are working. Set only with your consent where consent is required, and IP addresses are truncated.
Preferences
Small conveniences like a remembered theme, stored in your browser and never sent to us.

You can change or withdraw your choice at any time through your browser settings or the cookie control on this site. The platform itself uses only the cookies required to keep you signed in and secure.

12Security

  • Encryption in transit and at rest.
  • Role-based access, least privilege, and separate workspaces per client brand with no data shared between them.
  • Access logging and review, with credentials rotated on staff change.
  • Vendor review before a new sub-processor touches client data.
  • A documented breach process. Where a breach is notifiable we inform the relevant authority and affected people without undue delay, and in India we notify the Data Protection Board as required.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If you believe you have found a vulnerability, write to us and we will work with you on it.

13Children

The service is built for organisations and is not directed at children. We do not knowingly collect personal data from anyone under 18 in India, or under 16 in the EU and UK, and we do not carry out behavioural tracking or targeted advertising directed at children. If you believe a child's data has reached us, tell us and we will delete it.

14Changes to this policy

We update this page when what we do changes. The date at the top always reflects the current version. Where a change materially affects your rights we will give notice by email to clients and, where required, seek fresh consent rather than relying on a quiet edit.

Questions about this document